🔐 Finance & Admin

One identity layer for every campus role

User Management centralizes accounts, roles, and permissions so teachers, parents, counselors, and trust admins only see what their job requires — with an auditable trail.

Roles RBAC Access
Roles for every campus persona
Least-privilege access by default
Audit of permission changes
The problem

Why shared logins break campus security

When offices share passwords or grant “admin to everyone,” data leaks and nobody can prove who changed a fee waiver.

Shared passwords

Front desks reuse one login across shifts.

Over-powered accounts

Teachers get finance menus they never need.

Orphan users

Ex-staff accounts stay active after exit.

No proof

Auditors ask who approved a sensitive change.

Capabilities

What this module actually does

Operational depth your team will use every cycle — not a shallow feature list.

Role templates

Pre-built Admin, Registrar, Teacher, Counselor, Parent, and Trust roles.

Fine-grained permissions

Module and action-level grants (view, edit, approve, export).

Multi-campus scoping

Limit users to one branch or grant HQ rollups.

SSO-ready identities

Works with Google SSO and Azure AD when enabled.

Invite & onboard

Email invites with forced password reset.

Session controls

Timeout, device awareness, and forced logout.

Delegation

Temporary elevate for exam week without permanent admin.

Change audit

Log who edited roles and when.

Operating loop

How it works end to end

A clear path your staff and parents can follow without training manuals.

  1. 01

    Define

    Map roles to job functions.

  2. 02

    Invite

    Provision users from Staff or parent directories.

  3. 03

    Scope

    Attach campus and module permissions.

  4. 04

    Review

    Quarterly access audits with export.

Who uses it

Role-aware access for every stakeholder

The right people see the right slice of the pipeline.

Full RBAC

IT / Admin

Owns roles, SSO, and reviews.

Scoped admin

Principal

Approves elevated access.

Provision

Staff HR

Creates accounts tied to Staff Management.

Read logs

Auditor

Reviews access change history.

Outcomes

What changes after go-live

Measurable ops wins institutions report once this module runs inside ScholarERP.

Safer access across modules
Faster onboarding for new staff
Cleaner exit offboarding

“We stopped sharing the “office password.” Every action now has a named owner.”

IT Coordinator · Multi-campus trust
FAQ

Questions teams ask before buying

Straight answers for setup, integrations, and day-two operations.

Can parents and teachers share the same login type?

No. Personas use distinct roles and portals with least-privilege menus.

Does this replace Staff Management?

Staff Management is the HR record. User Management is the login & permission layer that can link to staff profiles.

Can we clone roles across campuses?

Yes. Start from templates, then scope campus-specific exceptions.

Is SSO required?

No. Password accounts work out of the box; Google SSO and Azure AD are optional.

Review role templates for your campus

Demo Admin, Teacher, Parent, and Trust roles on sample data.